808bits

BlackBerry Cryptographic Java Module

FIPS 140-2 certificate #2502 · BlackBerry Limited · data as of 2026-08-28
Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2502
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorBlackBerry Limited · website
Software versions2.8 [1], 2.8.7 [2], 2.8.8 [3]

Module description

BlackBerry is the leading wireless enterprise solution that allows users to stay connected with secure, wireless access to email, corporate data, phone, web and organizer features. BlackBerry is a totally integrated package that includes hardware, software and service, providing a complete end-to-end solution. The BlackBerry Cryptographic Java Module is a software module that provides cryptographic services to BlackBerryproducts such as the BlackBerry PlayBook Administration Service, and other BlackBerry products.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES1411, 3465
DRBG52, 852
DSA455, 978
ECDSA179, 702
HMAC832, 2210
KAS8, 61, 62
RSA687, 1776
SHS1281, 2860
Triple-DES964, 1954

Other algorithms

RNG; ARC2; ARC4; MD2; MD4; MD5; HMAC-MD5; DES; DESX; ECIES; ECQV; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECMQV (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); NDRNG;

Tested configurations

  • CentOS 7.0 with Java JRE 1.8.0 running on a Dell PowerEdge 2950 (single-user mode) [3]
  • Red Hat Linux AS 5.5 32-bit [1, 2]
  • Red Hat Linux AS 5.5 64-bit [1, 2]
  • Solaris 10 64-bit [1, 2]
  • Sun Java Runtime Environments (JRE) 1.5.0 and 1.6.0 running on Solaris 10 32-bit [1, 2]
  • Windows 2008 Server 64-bit [1, 2]
  • Windows Vista 32-bit [1, 2]
  • Windows Vista 64-bit [1, 2]

Validation history

DateTypeLab
2015-12-18InitialEWA - Canada
2016-01-22UpdateEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-12-18, 2016-01-22

Source documents